Privacy Policy
Last updated: June 2026
1. Who we are
RedCapra is a product of CapraSeed ("we", "us"). RedCapra is a local-first security audit workbench available at redcapra.com. Our contact email is support@redcapra.com.
2. What data we collect
Account data: When you sign up, we collect your email address and authentication provider details (Google SSO or email magic link) via Supabase Auth.
Scan data (Solo/free plan): All scan results, findings, and reports are stored locally in your browser. We do not transmit or store this data on our servers.
Scan data (paid plans): If you opt into cloud sync, scan data is stored in our cloud infrastructure (Vercel KV / Upstash) associated with your account. You can export or delete this data at any time.
Payment data: Payments are processed by Stripe. We do not store credit card numbers. We receive your Stripe customer ID and subscription status.
Support tickets: Messages sent via our support page are stored in our CapraDesk helpdesk system and associated with your email address.
Usage analytics: We collect basic analytics (page views, feature usage) via Vercel Analytics. No personal identifiers are attached.
3. How we use your data
We use your data to: provide and improve the RedCapra service, process payments and manage subscriptions, respond to support requests, and send transactional emails (account verification, support replies). We do not sell your data to third parties.
4. AI processing
If you use AI-assisted triage (Pro plan and above), your scan findings are sent to Anthropic's Claude API for analysis. This data is processed under Anthropic's data usage policy and is not used to train models. You can use RedCapra without AI features on any plan.
5. Data retention
Account data is retained while your account is active. Scan data on paid plans is retained until you delete it or close your account. Local-only data (Solo plan) is managed entirely by your browser and is not subject to our retention policies.
6. Your rights
You have the right to access, correct, export, or delete your personal data. To exercise these rights, contact us at support@redcapra.com. We respond to GDPR and CCPA requests within 30 days.
7. Security
We use HTTPS for all connections, Supabase row-level security for data isolation, and Stripe for PCI-compliant payment processing. Scan data on paid plans is encrypted at rest.
8. Cookies
We use essential cookies for authentication (Supabase session tokens). We do not use advertising or tracking cookies.
9. Changes
We may update this policy from time to time. Material changes will be communicated via the email associated with your account.
Questions about our privacy practices? Contact us at support@redcapra.com.
RedCapra